CVE-2024-29957: Encryption key is stored in the DR log files
Published Apr 19, 2024
·Updated
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.
Affected Software
2 affected components
Broadcom Brocade Sannav<2.3.0a
Brocade SANNav<2.3.1, <=2.3.0a
Event History
Apr 19, 2024
CVE Published
via MITRE·03:11 AM
Data Sourced
via MITRE·03:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29957?
The severity of CVE-2024-29957 is considered critical due to potential exposure of encryption keys.
2
How do I fix CVE-2024-29957?
To fix CVE-2024-29957, upgrade Brocade SANnav to version 2.3.1 or later.
3
What versions of Brocade SANnav are affected by CVE-2024-29957?
Brocade SANnav versions before 2.3.1 and 2.3.0a are affected by CVE-2024-29957.
4
What is the impact of CVE-2024-29957 on data security?
CVE-2024-29957 poses a risk to data security by potentially allowing unauthorized access to encryption keys.
5
Is there a workaround for CVE-2024-29957?
There is no official workaround for CVE-2024-29957; updating to the latest version is recommended.